Logical Methods in Computer Science 
Vol. 7 (1:13) 2011, pp. 1-21 
www.lmcs-online.org 



Submitted Feb. 09, 2010 
Published Mar. 29, 201 1 



RELATING COALGEBRAIC NOTIONS OF BISIMUL ATION * 



SAM STATON 



Laboratoire PPS, Universite Paris 7 
e-mail address: sam.staton@cl.cam.ac.uk 



Abstract. The theory of coalgebras, for an endofunctor on a category, has been proposed 
as a general theory of transition systems. We investigate and relate four generalizations of 
bisimulation to this setting, providing conditions under which the four different generaliza- 
tions coincide. We study transfinite sequences whose limits are the greatest bisimulations. 



Notions of bisimulation play a central role in the theory of transition systems. The theory 
of coalgebras provides a setting in which different notions of system can be understood at 
a general level. In this article I investigate notions of bisimulation at this general level. 

To explain the generalization from transition systems to coalgebras, we begin with the 
traditional presentation of a labelled transition system, 



(for some set L of labels). A labelled transition system can be considered 'coalgebraically' 
as a set X of states equipped with a function X — )• 'P{L x X), into the powerset of {L x X), 

assigning to each state x G X the set {{I, x') j x \x x'}. Generalizing, we are led to consider 
an arbitrary category C and an endofunctor B on it; then a coalgebra is an object X E C 
of 'states', and a 'next-state' morphism X — ?• B(X). 

Coalgebras in different categories. Coalgebras appear as generalized transition systems 
in various settings. For instance: transition systems for name and value passing process 
calculi have been studied in terms of coalgebras in categories of presheaves (e.g. \19\ [22| 
148]): probabilistic transition systems have been modelled by coalgebras for a probability- 
distribution monad (e.g. [6l |53]); descriptive frames and concepts from modal logic have 
been studied in terms of coalgebras over Stone spaces (e.g. [I]l9lf32]); basic process calculi 
with recursion have been modelled using coalgebras over categories of domains |31tl44j: and 
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stochastic transition systems have been studied in terms of coalgebras over metric and mea- 
surable spaces (see e.g. [12l [161 [521 [53] ) . Finahy, there are questions about the conventional 
theory of labelled transition systems in a more constructive universe of sets (e.g. 0). 

Notions of bisimulation. Once coalgebras are understood as generalized transition sys- 
tems, we can consider bisimulation relations for these systems. Recall that, for labelled 
transition systems {X, —^x) and {Y, -^y), a relation R X xY is a bisimulation if, when- 
ever xRy, then for all / G L: 

• For x' € X, if x \x x' then there is y' gY such that y \y u' and x' Ry'; 

• For y' ^ Y, if y \y y' then there is x' ^ X such that x \x x' and x' Ry'. 

How should the notion of bisimulation be generalized to the case of coalgebras for endo- 
functors on arbitrary categories? In this article, we identify four notions of bisimulation 
that have been proposed in the coalgebraic context. 

(1) A relation over which a suitably compatible transition structure can be defined, as 
proposed by Aczel and Mendler [2j; 

(2) A relation that is compatible for a suitable 'relation-lifting' of the endofunctor, as 
proposed by Hermida and Jacobs [25] ; 

(3) A relation satisfying a 'congruence' condition, proposed by Aczel and Mendler [2j and 
used to obtain their general final coalgebra theorem; 

(4) A relation which is the kernel of a common compatible refinement of the two systems. 
The four notions coincide for the particular case of labelled transition systems. Under 
certain conditions, the notions are related in the more general setting of coalgebras. 

Relationship with the terminal sequence. Various authors have constructed terminal 
coalgebras as a limit of a transfinite sequence; the initial part of the sequence is: 

1 <- B{1) 4^ B{B{1)) B{B{B{1))) ^ ■■■ ^ ... . 

Of the notions of bisimulation mentioned above, notions (2) and (3) can often be character- 
ized as post-fixed points of a monotone operator <I> on a lattice of relations. In this setting, 
by Tarski's fixed point theorem, there is a maximum bisimulation ('bisimilarity'). It is given 
explicitly as a limit of a transfinite sequence; the initial part of the sequence is: 

XxY ^ ^{XxY) D ^>($(X X y)) D $(^>($(X X y))) 

starting with the maximal relation, that relates everything. Under certain conditions, the 
steps of the terminal coalgebra sequence are precisely related with the steps of this relation 
refinement sequence. 

Other approaches not considered. In this article we are concerned with internal rela- 
tions between the state objects of two fixed coalgebras. A relation is itself an object of the 
base category. 

Some authors (e.g. [16j) are concerned with defining an equivalence relation on the 
class of all coalgebras, by setting two coalgebras as bisimilar if there is a span of surjective 
homomorphisms between them. Others work with relations as bimodules (e.g. |12 [ I45 [ [M]). 
We will not discuss these approaches here. 
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1. COALGEBRAS: DEFINITIONS AND EXAMPLES 
Recall the definition of a coalgebra for an endofunctor: 

Definition 1.1. Consider an endofunctor B on a category C. A B-coalgebra is given by an 
object X oi C together with morphism X — )■ B(X) in C. 

A homomorphism of i?-coalgebras, from {X, h) to (Y, k), is a morphism f : X ^ Y that 
respects the coalgebra structures, i.e. such that Bf o h = k o f . 

1.1. Examples. We collect some examples of concepts that arise as coalgebras for endo- 
functors. For further motivation, see [H 1261 H6]. 

Coinductive datatypes. Coinductive datatypes can be understood in terms of coalgebras for 
polynomial endofunctors. A polynomial endofunctor on a category with sums and products 
is a functor of the following form. (See e.g. Rutten [Ml Sec. 10].) 

X ^ ^ X A"^ 
ie/ 

(Here, each Ai is an object of the category, and each rii is a natural number.) 

Transition systems. In the introduction we discussed the correspondence between labelled 
transition systems and coalgebras for the endofunctor 'P{L x (— )). Here, V is the powerset 
functor, that acts by direct image. For finite non-determinism, and image-finite transition 
systems, one can instead consider the endofunctor 

Vi{L X (-)) 

where Vf is the finite powerset functor, the free semilattice. 

Transition systems in toposes and name-passing calculi. Recall that a topos is a category 
with finite limits and a powerobject construction. By definition, the powerobjects classify 
relations, and so the coalgebraic characterization of labelled transition systems is relevant 
in any topos. 

In process calculi such as the vr-calculus |41) . transitions occur between terms with free 
variables, and those free variables play an important role. Conventional labelled transition 
systems in the category of sets are inadequate for such calculi. Instead, one can work 
in a category of covariant presheaves (C — ?> Set). Various categories have been proposed 
for C. We will focus on two examples: the category I of finite sets and injections between 
them, and the category of non-empty finite sets and all functions between them. More 
sophisticated models of process calculi are found by taking presheaves over more elaborate 
categories (see e.g. piil fTTl [221 H9] ) . 
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In this setting, the object X of states is no longer a set, but a presheaf. For instance, if 
X : I —?■ Set, we think of X{C) as the set of states involving the free variables in the set C, 
and the functorial action of X describes injective renaming of states. 

The appropriate endofunctor on these presheaf categories typically has the following 
form 

V{B'{-)) where e.g. S'(-) = (iV X (-)^ + iV X iV X (-) + (-)) (1.1) 

with the summands of B' representing input, output, and silent actions respectively. The 
presheaf is a special object of names. The interesting question is: what is 

• A natural choice is to let V be the powerobject functor in the presheaf topos [C,Set]. 
For any presheaf Y € [C,Set], and any object C G C, {V{Y)){C) is the set of sub- 
presheaves of (C(C, — ) x Y). A coalgebra X V{B'[X)) is a natural transformation 
between presheaves, that assigns a behaviour to each state x € X{C), for C G C. This 
behaviour is not only a set of future states for x, but also the future states of X f{x) for 
any morphism / : C ^ C" in C. 

To understand this more formally, recall that the powerobject V classifies relations in 
the following sense. For presheaves X and Y in [C, Set], there is a bijective correspondence 
between natural transformations r: X — > V{Y) and subpresheaves i? C X x y. A 
subpresheaf C X x y determines a natural transformation r: X ViY)] for C G C 
and X G X{C), we have rdx) G {V{Y)){C): 

{rc{x)){C') = {U,y) I {Xf{xly)^R{C')} . 

• The powerobject V{X) accommodates infinite branching transition systems. To focus on 
finite branching, we can find a 'finite' subfunctor of V. 

The approach taken by Fiore and Turi [19] is to let V be the free semi-lattice (hence- 
forth V{). This is sometimes called 'Kuratowski finiteness'. For any presheaf Y G [C, Set], 
and any object C G C, {Vi{Y)){C) is the set of finite subsets of Y{C). We have an natural 
monomorphism iy Vi{Y) ^ ViY) into the fuh powerobject: for C G C, 5 C (y(C)), 
we define a subpresheaf iY,c{S) G {V{Y)){C): 

iiY,ciS)){C') = {(/,y/(2/)) \f:C^C',yeS} . 

• The free semilattice is too naive on the presheaf category [¥+,861]. For example, the 
TT-calculus process (a | b) cannot perform a r-step, but it can perform a r-step after 
the substitution {a i— )• 6, 6 i— )• 6}. The construction 'Pf{X) is too small to allow this 
information to be recorded. Indeed, the vr-calculus can be described as a coalgebra for 
the functor V{B'{—)) on [F^,Set], but this coalgebra does not factor through the free 
semilattice, Vf{B' {—)). 

In this situation, a more appropriate finite powerset is the sub-join-semilattice of the 
powerobject V{Y) that is generated by the partial map classifier. We will write Vp{{Y) 
for this — Freyd j20j writes K. I gave an algebraic description of this construction in 
[50] , and it has been used by Miculan in his model of the fusion calculus ^37j . 

Frames in modal logic. Let the base category C be the category of Stone spaces and con- 
tinuous maps. (A Stone space is a compact Hausdorff space in which the clopen sets form 
a basis.) Let K{X) be the space of compact subsets of X, with the finite (aka Vietoris) 
topology. The construction K is made into a functor, acting by direct image. Coalgebras 
for K can be understood as descriptive general frames. Just as the category of Stone spaces 
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is dual to the category of Boolean algebras, the category of K-coalgebras is dual to the cat- 
egory of modal algebras (i.e., Boolean algebras equipped with a meet-preserving operation) 
— see e.g. HIES]. 



Powersets in algebraic set theory. A general treatment of powersets is suggested by the 
algebraic set theory of Joyal and Moerdijk [29j. A model of algebraic set theory is a 
category C together with a class of 'small' maps S in C, all subject to certain conditions. 
An intuition is that a map f : X ^ Y is small if its fibres f~^{y) are all small. 

In such a situation, an S-relation is a relation C X x y for which the projection 
R ^ X \s 'vo.S. An endofunctor Pg on C is said to be the S-powerset if there is an iS-relation 
(9y) C Pg(Y) X Y inducing a bijective correspondence between <S-relations {R Q X x Y) 
and morphisms X — > Ps(Y). Further details are given in the appendix. 

These ideas cater for the notions of power set discussed so far. For instance: 

• Let C be the category of sets, in the classical sense, and say that a function f : X —?■ Y 
is small if for every y £ Y the set f~^{y), i.e. {x £ X \ f{x) = y}, is finite. This class 
S of maps satisfies all the axioms for small maps given in the appendix. An iS-relation is 
precisely an image-finite one, and the 5-powerset is the finite powerset. 

• For a presheaf category [C,Set], the free semilattice construction Vf is an 5-powerset 
where S is the class of natural transformations between presheaves, (j)'- X ^ Y, such that 
(i) for each C G C, y G Y{C), the set {x € X{C) \ fc{x) = y} is finite, and (ii) each 
naturality square is a weak pullback, i.e., if (j)c'{x') = Yf(y) then there is a; € X{C) such 
that (pcix) = y and Xf{x) = x': 

X{C)^^Y{C) (1.2) 



YU) 



xiC) — ^y(c'). 

'I'ci 

This class S of morphisms always satisfies Axioms A1-A6 and A9 for small maps, but 
not (M): monos are not small unless C is a groupoid. 

In the presheaf category [F"*" , Set] , the free semilattice generated by the partial map 
classifier, Ppf , is more liberal: it classifies the natural transformations between presheaves 
that satisfy the finiteness condition (i) but the requirement on naturality (ii) is weakened 
to the situation when / is an injection. This class of morphisms satisfies all the axioms 
for small maps, including (M). (This argument is quite specific to F+.) 
Let C be the category of Stone spaces, and let K[X) be the space of compact subsets of 
X. Recall that a continuous map is open if the direct image of an open set is open. The 
class S of open maps in the category of Stone spaces satisfies Axioms A1-A6 and A9 for 
small maps. The evident relation 3x ^ K{X) x X is an 5-relation, and exhibits each 
K{X) as an 5-powerset. 

(Although the Vietoris construction can be considered over more general spaces, the 
characterization of K as an iS-powerset is specific to Stone spaces. This raises the question 
of how best to treat more expressive positive/top ological set theories [36] in an algebraic 
setting.) 



6 



S. STATON 



Probabilistic transition systems. For any set X, let 'Df{X) be the set of sub-probability 
distribution functions on X, viz., functions from d: X — )• [0,1] into the unit interval for 
which {x € X \ d{x) ^ 0} is finite and Ylx&x ^(^) — ^- This construction extends to an 
endofunctor on Set, with the covariant action given by summation. Coalgebras for Df are 
discrete probabilistic transition systems [U [53] . 

Systems where the state space has more structure. For continuous stochastic systems, re- 
searchers have investigated coalgebras for probability distribution functors on categories of 
metric or measurable spaces (see e.g. \T6 \ \52 l [53]). 

For recursively defined systems, it is reasonable to investigate coalgebras for powerdo- 
main constructions on a category of domains (in the bialgebraic context, see |31[ 144]). 

Levy and Worrell |35[ have considered endofunctor s on categories of preorders, 
posets, and categories enriched in quantales, in their investigations of similarity. 

2. BiSIMULATION: FOUR DEFINITIONS 

We now recall four notions of bisimulation on the state spaces of coalgebras. The four 
notions generalize the standard notion of bisimulation for labelled transition systems (i.e. 
coalgebras for 'P{L x (— )) on Set), due to Milner [40j and Park ^43j . For all four notions, 
the maximal bisimulation is the usual notion of strong bisimilarity for labelled transition 
systems. 

To some extent, the different notions of bisimulation have arisen from the examples in 
Section II. 1[ as authors sought coalgebraic notions of bisimulation that were appropriate to 
the base category and endofunctor under consideration, as well as to the intended applica- 
tions. For name-passing calculi, coalgebraic bisimulation can be used to capture the bisim- 
ulations of Milner, Parrow and Walker [5T] and also the open bisimulation of Sangiorgi |47] 
(see e.g. [IHl [501 Sec. 6]); for discrete-space probabilistic systems, coalgebraic bisimulation 
can describe the probabilistic bisimulation of Larsen and Skou [3l] (see e.g. [53]). 

Relations in categories. For objects X,Y of a category C, we let Relc(X, Y) be the preorder 
of relations, viz. jointly-monic spans X -(^ R ^ Y , where R < R' if R factors through R'. 
When C has products, the preorder Relc(X, y) coincides with the preorder of monos into 
{X X Y). Relations are most well-behaved in regular categories (see Appendix). 

Context. In this section we fix a category C and consider an endofunctor B on C. We fix 
two i?-coalgebras, h : X ^ BX and k -.Y ^ BY. 



RELATING COALGEBRAIC NOTIONS OF BISIMULATION 



7 



2.1. The lifting-span bisimulation of Aczel and Mendler [2j. This notion is categor- 
icahy the simplest. It directly dualizes the concept of congruence from universal algebra. 

Definition 2.1. A relation i?€Relc(X, y) is an AM-bisimulation between {X,h) and 
{Y, k) if there exists a i?-coalgebra structure on R that lifts it to a span of coalgebra 
homomorphisms, as in the following diagram. 



X 



BX 



-R- 

\ 3 

BR- 



-Y 

k 

BY 



2.2. The relation-lifting bisimulation of Hermida and Jacobs [25]. The following 
is a simplification of the bisimulation of Hermida and Jacobs, who work in a more general 
fibrational setting. 

Definition 2.2. Let C have products and images. (See the Appendix for definition.) For 
any relation R € Relc(A, Y), we define the relation BR E Tielc{BX, BY) to be the image 
of the composite morphism BR — > B{X x y) — )■ BX x BY. (The construction B is called 
the "relation lifting" oi B.) 

A relation R in Relc(A, y) is an H J -bisimulation if there is a morphism R — )• B[R) 
making the following diagram commute. 



X 



R 



Y 



BX 



BR 



BY 



When C has pullbacks, let $^■'(7?) be the following pullback: 



I ^ 

A X y - 



BR 



hxk 



BX X BY 



□ 



By definition, a relation R is an H J -bisimulation if and only if i? < <I>^'^(i?). 

Proposition 2.3. The operator <1>^'^ on Relc(A, y) is monotone. 

For illustration, we briefiy return to the situation of transition systems, where C = Set 
and B = V{L x — ). For any relation R G Relc(A, y), the refined relation <l>^'^(i?) in 
Relc(A, y) is the set of all pairs (x, y) € A x y for which 

(i) V(/, x) G h{x). V e Y- {I, y') e Hv) and {x' , y') £ R ; 

(ii) V(/,y') G k{y).3x' G A. {l,x') G /i(x) and {x',y') G i? . 
Thus the operator <I>^'^ is the construction J-" considered by Milner [39\ Sec. 4]. 
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2.3. The congruences of Aczel and Mendler [2]. 

Definition 2.4. A relation R in Relc(X, y) is an AM-precongruence if for every cospan 
{X ^ Z ^ Y), 

^X^ ^X^BX ^ 

if i? Z commutes then so does R BZ 

Y Y — ^ BY 

The definition might appear clumsy and unmotivated, but AM-precongruences are of pri- 
mary interest because of their connection with terminal coalgebras in a general setting, as 
will become clear in Theorem 14.11 

If C has pushouts, then it is sufficient to check the case where Z is the pushout of R. 
If C also has pullbacks, let <^^^(i?) be the pullback of the cospan 

X \ BX ^ BZ <^ BY ^ Y . 

By definition, a relation R is an AM-precongruence if and only if < 

Proposition 2.5. The operator <I)^^ on ReIc(A, y) is monotone. □ 

(Note that is different from <I>^'^, even when B is the identity functor on Set.) 

Our definition differs from that of [2] in that we consider relations between different 
coalgebras. The connection is as follows: if {X,h) = {Y,k), then an equivalence relation is 
an AM-precongruence exactly when it is a congruence in the sense of Aczel and Mendler [2] 
(see Section [^?2|) . 



2.4. Terminal coalgebras and kernel-bisimulations. Many authors have argued that 
when the category of coalgebras has a terminal object, equality in the terminal coalgebra is 
the right notion of bisimilarity. Suppose that the category C has pullbacks, and suppose for a 
moment that there is a terminal i?-coalgebra, (Z, z). This induces a relation in Relc(A, Y) 
as the pullback of the unique terminal morphisms A — > Z ^ 1". The relation is sometimes 
called 'behavioural equivalence'. 

We can formulate a related notion of bisimulation without assuming that there is a 
terminal coalgebra. 

Definition 2.6. Let C have pullbacks. A relation i? is a kernel-bisimulation if there is a 
S-coalgebra (Z, z) and a cospan of homomorphisms, (A, h) — > (Z, z) ^ {Y, k), and R is the 
pullback of (A ^ Z ^ y). 

Aside from the great many works involving terminal coalgebras, various authors (e.g. |24| 
[3H I33j) have used kernel-bisimulations (though not by this name). (The term 'cocongru- 
ence' is sometimes used to refer directly to the cospan involved.) 
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3. Properties of endofunctors 

All the definitions of the previous section are relevant when C is a regular category. Prom 
a categorical perspective, one might restrict attention to endofunctors that are regular, i.e. 
that preserve limits and covers. But none of the endofunctors in Section 11.11 are regular. 
We now recall five weaker conditions that might be assumed of our endofunctor B. 
(1) The image of a relation under a functor need not again be a relation, and one can 

restrict attention to endofunctors that preserve relations, i.e., for which a jointly- monic 

span is mapped to a jointly-monic span. 
The remaining restrictions have to do with weak forms of pullback-preservation. To in- 
troduce them, we consider a cospan (Ai Z A'l) in C, and in particular the mediating 
morphism m: B(^A\ A2) — )• {BA\) Xbz {BA2) from the image of the pullback to the 
pullback of the image: 




Here are some conditions on B, listed in order of decreasing strength. 

(2) B preserves pullbacks if m is always an isomorphism. 

(3) B preserves weak pullbacks, if m is always split epi. Gumm [23] describes several equiv- 
alent definitions of this term. 

(4) B covers pullbacks if m is always a cover. The terminology is due to [51]. Note that a 
split epi is always a cover. 

(5) B preserves pullbacks along monos if m is an isomorphism when — )• Z is monic. 
Tying up with relation preservation (1): B preserves pullbacks if and only if it preserves 
relations and covers pullbacks (see Carboni et al. [HI Sec. 4.3]). 



3.1. Relevance of the properties. 
Proposition 3.1. 

(1) Let be one of the following properties: relation preservation, pullback preservation, 
weak pullback preservation, preservation of pullbacks along monos. The composition of 
two endofunctors satisfying ^ also satisfies ^. 

(2) If B and B' both cover pullbacks and B' preserves covers, then the composite (B'B) 
also covers pullbacks. □ 

Proposition 3.2. Every polynomial endofunctor on an extensive category preserves pull- 
backs and covers. □ 

Regarding powerset functors from algebraic set theory (see Appendix), we have the 
following general results. 

Proposition 3.3. Let C be regular, and let S be a class of open maps in C. Suppose that 
Ps is an S-powerset. 

(1) The functor Pg preserves pullbacks along monomorphisms. 

(2) If S contains all monomorphisms (M), then Pg preserves weak pullbacks. 
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(3) Let C also be extensive, and let S satisfy the axioms for extensive categories (ax- 
ioms (Al-6)) and also collection (A9), hut not necessarily (M). The functor covers 
pullbacks. 

Proof of Propn. \3.3l I will sketch proofs in the set-theoretic notation. Translation into 
categorical language is straightforward. 

For item ([1]), consider a pullback square, and its image under Pg. 

f-\Z') « A PsU-\Z')) Ps{A) 

J 



/ 



Psf 



Z'> Ps{Z') ^Ps{Z) 

To see that the right-hand square is a pullback, consider S in Ps{A), for which the direct 
image Psf{S) is in Ps{Z'); then, by definition, S is in Ps{f~^{Z')). 

For items ([2]) and ([3]), consider a cospan (^i Z A2). For item ([2]), we must 
exhibit a section s : Ps{Ai) Xp^f^z) -^5(^2) Ps[-Ai A2) of the canonical morphism. 
For (5i,52) in ^5(^1) XPs{Z) PsiM), note that 

Vai G Si. 3a2 G 5*2. /(oi) = 5(02) and Va2 G 5*2. 3ai G ^i. /(ai) = §{02) 

and let 

s(5i,52) = {(01,02) G (5i X S2) I /(ai) = 5(02)} . 
Here we have used the separation axiom, which is valid when all monomorphisms are small. 
For item ([3]), we show that the canonical morphism 

PsiAi Xz A2) ^ PsiAi) xp^^z) Ps{A2) 

is a cover. Consider (Si, 52) in Ps{Ai) Xp^^z) -P<s(^2); we must show that there is S in 
^5(^1 Xz A2) whose direct image is (5i,52). 

By the (strong) collection axiom, we have Ti in ^5(^1 Xz A2) such that vri(ri) = Si 
and vr2(Ti) C S2- Similarly, we also have T2 in ^5(^1 Xz A2) such that 7r2(T2) = S2 and 
'T^\^2) ^ Si. Thus (Ti UT2) is in Psi^Ai XZA2), and its direct image is {Si, S2), as required. 
Thus Propn. 13.31 is proved. □ 

The free semi-lattice functor Vi on any topos covers pullbacks, but will only preserve 
weak pullbacks if the topos is Boolean. In general, the corresponding class of small maps 
does not contain all monomorphisms, as Johnstone et al. \27\ Ex. 1.4] have observed. The 
counterexample of [27] is easily adapted to the settings of the presheaf categories for name 
passing, correcting oversights in [22l HH] . 

On the other hand, the endofunctor Vpi on the presheaf category Set] does preserve 
weak pullbacks. 

The compact-subspace endofunctor K on Stone spaces covers pullbacks (a consequence 
of Propn. 13. 3p although it does not preserve weak pullbacks, as observed by Bezhanishvili 
et al [H]. 

The probability distribution functor T>{ on Set preserves weak pullbacks [42| 1533. 

More sophisticated continuous settings are problematic. Counterexamples to the weak- 
puUback-preservation of probability distributions on measurable spaces are discussed in |52j . 
Plotkin |44j discusses problems with coalgebraic bisimulation in categories of domains: the 
convex powerdomain does not even preserve monomorphisms. The endofunctors on posets 
that Levy considers |35j typically do not preserve monomorphisms either. 
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4. Relating the notions of bisimulation 



The purpose of this section is to relate the four notions of bisimulation introduced in Sec- 
tion [3 

Theorem 4.1. Let B he an endofunctor on a category C with finite limits and images. 

(1) Every AM-hisimulation is an H J -bisimulation. 

(2) Every H J -bisimulation is an AM-precongruence. 

(3) Every AM-precongruence is contained in a kernel bisimulation that is an AM-precon- 
gruence, provided C has pushouts. 

(4) Every kernel bisimulation is an AM-hisimulation, provided B preserves weak pullbacks. 

(5) Every kernel bisimulation is an H J -bisimulation, provided B covers pullbacks. 

(6) Every kernel bisimulation is an AM-precongruence, provided B preserves pullbacks along 
monos and C is regular. 

(7) Every H J -bisimulation is an AM-bisimulation, provided either 

(i) every epi in C is split, or 
(a) B preserves relations, or 

(Hi) C is regular with a class S of open maps containing all monomorphisms, and there 
is an S-powerset Pg, and B{—) = Ps{B'{—)), for a relation preserving functor 
B'. 

(iv) C is a topos and B = P[B'[—)), where P is the powerobject of C and B' is an 
arbitrary endofunctor. 



In summary: 



(4) 



pres. weak p'backs 



AM-bisim. 


(1) 


HJ-bisim. 


(2) 








(7i)-(7iv) 




Note that the different notions of bisimulation are not, in general, the same. For 
instance, Aczel and Mendler [S] p. 363] provide an example of an endofunctor on Set for 
which there is an AM-precongruence that is not an AM-bisimulation. Bezhanishvili et al. [9] 
Sec. 4] demonstrate that AM-bisimulation is different from HJ-bisimulation for the Vietoris 
construction on Stone spaces. 



4.1. Proof of Theorem I47TI Throughout the proof, we fix two i?-coalgebras, h : X ^ BX 
and /c : y ^ BY. 

Item ([1]) is trivial. 
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For item ([2]), let R be an HJ-bisimulation. Let {X —^Zi- 
{X ^ R ^ Y). Consider the following commuting diagrams. 



Y) be a cone over the span 



(a) 



R 



X 



BR 



Y 



BX 



BY 



(b) 



BZ 



BR 



BX 



BY 



BZ 



The left-hand squares of diagram (a) say that R is an HJ-bisimulation. The right-hand 
square of diagram (a) commutes since diagram (b) commutes, and BR — > BR is epi. Thus 
the whole of (a) commutes, and R is an AM-precongruence. 

For item ([31), let R be an AM-precongruence. Let {X Z Y) he the pushout of the 
span {X ^ R Y). The following diagram commutes; the dotted morphism follows from 
universality of the pushout. 




Let {X -i^ R' ^ Y) be the pullback of (X — )■ Z ^ y). By definition, it is a kernel 
bisimulation. Moreover, the pushout of (X ^ R' Y) is Z again, so R' is an AM-precon- 
gruence. 

For items ([4]), ^ and ([6]), let be a kernel bisimulation, the pullback of a cospan 
{X — 7> Z ^ y), for some coalgebra {Z, z). Note that the following diagram commutes. 




X 



Y 



BX 



BY 



(4.1) 



BZ 



For item (jl]), we must show that R is an AM-bisimulation. We construct a coalgebra 
structure on R by considering the morphism R — ?> BR induced since BR is a weak pullback, 
as in the following diagram. 

h 




X 



BR 



Y 



BX 



BY 



BZ 



For item ([5]), we must show that R is an HJ-bisimulation. This follows from the following 
fact, which is immediate from the definition of BR, and which is worth recording: 

Fact 4.2. If B covers pullbacks, then 

X BX 

\i R Z IS a pullback, so is BR BZ 

Y BY 
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For item ([6]), we must show that R is an AM-precongruence. This is more involved. 
We make use of the following lemma. 

Lemma 4.3. Consider objects S, S' , V, V , and morphisms p,q,p' ,q' , f, g, f , g' , making 
the following three diagrams commute. 



s:^^^ (a) 

Y 



p'X ^ 

S' ^ (b) 



Y 



BX^Bf 



BY ^3 



BV (c) V' 



If the left-hand diagram is a pullback, and B preserves puUbacks along monos, and C is 
regular, then the following diagram also commutes. 



h 



p'X " 

S' ^ w 



Y 



BX Bf 



BV 



BY ^9' 



Proof of Lemma \4.3\ Write im(/) for the image oi f : X ^ V , etc.. Subdivide the 
pullback (a) as follows. 

(4-2) 

im(p) > iin(/) 

\m.{q) > im((7) 

Since C is regular, the composite S ^ W is regular epi. In this situation, the leftmost 
pullback is also a pushout, as indicated (see e.g. [HI Thm 5.2].) 

Since diagram (b) commutes, and since B preserves pullbacks along monos, we have 
unique morphisms S' — )• B(\m{p)) and S' — )• B(\m{q)) making the following diagram com- 
mute. 

X ^^BX ^ 

p' ^ 



s' :::::: 




i?(im(p)) 



5(im(g)) > 



Y 



BW 



BY 



B([m{f)) 
'B{im{g))' 



BV 



Now consider diagram (c). Since is a pushout, we have a unique morphism W —> V 
making the following diagram commute. 

im{p) > *- X fi 

im(g) > ^ Y 
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We can now conclude diagram (d), by combining the previous two diagrams as follows. 




Y ^BY 



Thus Lemma 14.31 is proved. □ 
Returning to the proof of Theorem 14.11 notice that item ([6]) follows from Lemma 14.31 in the 
case S = S' = R, V = Z . 

Item (I7|) of Theorem 14.11 gives conditions under which every H J-bisimulation is an AM- 
bisimulation. The following fact is crucial here: 

Fact 4.4. An HJ-bisimulation R is an AM-bisimulation if the cover BR — > BR is split. □ 

Case ([7i|) . where all epis split, is thus trivial, and in case (|7iip . where B preserves 
relations, the cover is an isomorphism. In cases ()7iiip and (|7ivp . we define a section 
BR BR = Ps (B'R) by defining the following composite relation (BR ^ • ^ B'R) : 

BR ^B'X X Bb'Y B'R 




BR BX X BY B'X x B'Y B'R 

In case ()7iiip . we must check that the composite relation is an tS-relation. By the axioms of 
open maps, it is sufficient to check that all the leftwards morphisms in the composite are 
in S. The right-most leftwards morphism is in S because B' preserves relations, hence it is 
monic. 

This concludes our proof of Theorem 14. 1[ 

4.2. A note about equivalence relations. When {X, h) = {Y, k) then the maximal 
bisimulation, when it exists, is often an equivalence relation. Some authors focus attention 
on those bisimulation relations that are equivalence relations. In this setting, it is reasonable 
to adjust the definition of kernel bisimulation, so that the two coalgebra homomorphisms 
X ^ Z are required to be equal. An appropriate adjustment of Theorem 14.11 still holds 
even when the pullback-preservation requirements are weakened as follows: 

• In item ([3]), it is not necessary for C to have pushouts, it is sufficient for C to have effective 
equivalence relations (i.e., that every equivalence relation arises as a kernel pair); 

• In item ([5]), it is not necessary for B to preserve weak pullbacks, it is sufficient for B to 
weakly preserve kernel pairs; 

• In item (l5|), it is not necessary for B to cover pullbacks, it is sufficient that B covers 
kernel pairs; 

• In item it is not necessary for B to preserve pullbacks along monos, it is sufficient 
for B to preserve monos. (In diagram ()4.2p . \i f = g then W = im(/) = un^g).) 
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The conditions are connected: in an extensive regular category, a functor covers pullbacks 
if and only if it covers kernel pairs and preserves pullbacks along monos. (Gumm and 
Schroder [24j showed this for Set, and their argument is readily adapted to this more 
general setting.). 

In summary, we have the following situation, when focusing on equivalence relations: 




5. Constructing bisimilarity 

In this section we consider a procedure for constructing the maximal bisimulation. We 
relate it with the terminal sequence, which is used for finding final coalgebras. 

Context. In this section we assume that the ambient category C is complete and regular. 
We fix an endofunctor B on C, and fix two i?-coalgebras, h : X ^ BX and /c : y — > BY . 

5.1. The relation refinement sequence. The greatest HJ-bisimulations can be under- 
stood as greatest fixed points of the operator on Relc(X, y). We define an ordinal 
indexed cochain (r^,a : I^'^ ^ I^'^)a<i3 in R-elc(-^, in the usual way: 

• Limiting case: If A is limiting, then let i?^'^ be flcKA-^a''' limit of the cochain 
(r^^Q, : Fdp'^ ^ -Ra"')a<^<A- In particular, let B^'^ = X xY. 

• Inductive case: let -R^+i = <I>^'^(-R^''). 

We call this cochain the relation refinement sequence. If this sequence is eventually station- 
ary then it achieves the maximal post-fixed point of (^^■^ , the greatest HJ-bisimulation. (NB. 
The sequence always converges when Relc(X, y) is small, e.g. when C is well-powered.) 

For the case of the endofunctor V{L x (— )) on Set, the relation refinement sequence is 
a transfinite extension of Milner's sequence ~o ^ ~i ^ • • • > ~ (e.g. [381 Sec. 5.7]), studied 
from an algorithmic perspective by Kanellakis and Smolka |30j . 

If C has pushouts, we can also consider a cochain {R^^ ^ Ra^)a<i3 corresponding to 

the operator As will be seen, the two sequences of relations often coincide. 

(The other notions of bisimulation, AM-bisimulation and kernel bisimulation, cannot 
be characterized as post-fixed points, in general.) 
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5.2. The terminal sequence. There is another sequence that is often studied in the 
coalgebraic setting. The terminal sequence is an ordinal-indexed cochain 

that can be used to construct a final coalgebra for an endofunctor (e.g. Worrell [55]). The 
idea is to begin with the terminal object, and then successively find B-algehra structures, so 
that if the sequence converges, i.e. the -B-algebra structure is an isomorphism, then we have 
a B-coalgehra structure, and indeed the final such. The cochain commutes and satisfies the 
following conditions: 

• Limiting case: Z\ = limjz^ Q, : — )• | a < /3 < A}, if A is limiting, in which case the 
cone {zx^a ■ Zx ^ Za \ a < X} is the limiting one; 

• Inductive case: Z^+i = B{Za)\ and 2;/3+i,q+i = B{zi3^a) ■ ^/3+i ^ Z^+i- 



5.3. Relating the relation and terminal sequences. The coalgebras {X,h), (Y,k) de- 
termine two cones 

{Xa ■ X — )• Za)a {Ua '■ Y — )• Za)a 

over the terminal sequence. The first cone, {xa)a is given as follows. 

• Limiting case: If A is a limit ordinal then the morphisms Xa ■ X —?■ Za for a < A form a 
cocone over the cochain (z/s^a '■ Z^ Za)a<i3<\^ with apex X. We let xx '■ X ^ Zxhe the 
unique mediating morphism. For instance, when A = 0, then xx '■ X ^ Zx is the terminal 
map X ^ I. 

• Inductive case: Let Xa+i be the composite 

Ji. r ijJi. r dZjqi — ^Q,-|_x 

The other cone, {ya ■ X — )• Zq,)q,, is defined similarly. 

These cones determine another ordinal indexed cochain (i?^ ^ Ra)a<p in R'elc(X, y). 
For every ordinal a, let Ra be the following pullback. 




Theorem 5.1. Consider an ordinal a. 

(1) Ra contains all the kernel hisimulations and all the AM-precongruences. 

(2) If B covers pullbacks, then Ra = Ra"^ ■ 

(3) If B preserves pullbacks along monos, and C has pushouts, then Ra = R^^- 

Proof. To see that Ra contains all the kernel bisimulations, notice that for a cospan of 
coalgebras, {X Z ■^Y), the coalgebra Z determines a cone over the terminal sequence, 
just as X and Y do. The relation Ra contains all the AM-precongruences by transfinite 
induction on a: the limit step is vacuous and the inductive step uses the definition of AM- 
precongruence. Statements (2) and (3) are also proved by transfinite induction on a: the 
limit steps use the fact that limits commute with limits; the inductive steps follow from 
Fact 14.21 and from Lemma 14.31 respectively. □ 
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Note. A consequence of Item (3) of Theorem 15.11 is that, if the sequence [Rp ^ Ra)a<p 
converges, then the result is the greatest AM-precongruence, provided the endofunctor 
preserves puhbacks along monos and C has pushouts. In fact, this corollary still holds even 
if C does not have all pushouts. This can be proved directly by transfinite induction; the 
inductive step uses Lemma HTSl 



5.4. Convergence for the relation refinement sequences. By Theorem 15. 1|, if the 

terminal sequence converges, then the relation refinement sequence does too. Of course, 
this is not a sufficient condition. Indeed, even when there is a final coalgebra, the relation 
refinement sequence may converge before the terminal sequence: 



Proposition 5.2. If, for some ordinal a, the morphism z^^i^a '■ -^a+i 

Ra = Ra+1- 



Za is monic, then 



Proof. We have the following situation. 



R. 



XxY 



A 



Xa+lXya+1 



z 



a+1 



Za X Za 



The left-hand square is a pullback — this is a rearrangement of the definition of Ra+i- The 
right-hand square is a pullback if and only if Za+i,a is monic. Thus the outer square is a 
pullback. Now Xa = {xa+i ■ Za+i a) and Ha = {Va+i • Za+i a), which means that Ra+i = Ra- 

□ 

If C is Set and B preserves filtered colimits, then the terminal sequence does not 
converge until (w + co), but it becomes monic at w [55]. As is well-known, the relation 
refinement sequence for image-finite transition systems converges at co. 

For the case when C = Set and sets X and Y are both finite, the relation refinement 
sequence will converge before co because the skeleton of Relc(X, Y) is finite. This is relevant 
in a slightly more general setting: In a Boolean Grothendieck topos, every descending 
cj-cochain of subobjects from a finitely presentable object is eventually constant. 

The presheaf topos [I, Set], used to model name-passing, is not Boolean. It does, 
however, have Sh-,-,(I) as a Boolean subcategory, and this is perhaps a more appropriate 
universe for name-passing calculi (see e.g. [IBJ). There, the finitely presentable objects are 
exactly those objects that can be described by finite 'named-sets with symmetry' [18^ \2T\. 
Thus the techniques of this article provide a general foundation for the coalgebra-inspired 
verification procedures of Ferrari, Montanari and Pistore (17j . 



Appendix A. Some concepts from categorical logic 

We recall some concepts from categorical logic: regular categories; and powersets from 
algebraic set theory. 
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A.l. Regular and extensive categories. An image of a morphism / : ^ ^ C is a 
monomorphism m : B ^ C through which / factors, which is minimal in the sense that, if 
/ factors through any other mono, B' ^ C, then B is a. subobject of B' . In this setting, 

the factoring morphism f : A —> B is called a cover; its image is B ^ B. A category has 
images if every morphism has an image. 

In a category with finite limits, covers are epimorphisms. They serve as a generalization 
of 'surjective function'. In this setting, other authors refer to covers as strong epimorphisms. 

A category with finite limits and images is said to be regular if covers are stable under 
puUback, i.e., if the following diagram is a pullback, and if / is a cover, then so is /'. 

(A.l) 




Recall that a category is said to be extensive if it has coproducts and they are disjoint 
and stable under pullback (see e.g. [15]). 



A. 2. Open maps, powersets, and algebraic set theory. We now recall an analysis of 
'smallness' due to Joyal and Moerdijk [281 [29]. (For ^ more recent introduction to this area 
of research, see the articles by Awodey [5] and by van den Berg and Moerdijk |8].) 

An intuition for this analysis is that a morphism f : A ^ B describes a i?-indexed 
family of classes — informally, for each element b of B, we have a class f~^{b). When we 
say that a morphism f : A ^ B is small, an intuition is that each fibre f~^{b) is small. In 
particular, we say that an object A is small if the terminal map yl — > 1 is small. 



Open maps in regular categories. Let C be a regular category. A class S of morphisms in C 
is a class of open maps if it satisfies the following four axioms. (This numbering follows 

m-) 

(Al) S is closed under composition, and all identity morphisms are in S. 
(A2) S is stable under pullback, i.e., in diagram (jA.ip . if / is in S, then /' is also in S. 
(A3) ('Descent') In diagram (jA.ip . if /' is in S and g is a cover, then / is also in S. 
(A6) In the following triangle, if / is in 5 and e is a cover, then g is also in S. 

A^^A' 




Most authors assume that C has additional structure so that the universal quantifier can 
be interpreted in C. We do not need that in this article. 



Sums and open maps. In an extensive regular category, it is appropriate to assume the 
following additional axioms. 
(A4) The maps — > 1 and 1 + 1—^1 are in S. 

(A5) If ^ ^ ^' and B ^ B' are in S, then so is {A + B)^ [A' + B'). 
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Powersets. Given a regular category C and a class of open maps S, an 5-relation is a jointly 
monic span (I R —?■ A) whose left projection is in S. 

An 5-powerset for an object ^4 of C is an object Psi^) together with an 5-relation 
{Ps{A) ^ 3a — >■ A) such that for every 5-relation {I R ^ A) there is a unique morphism 
/ PsiA) making {R ^ I x A) a pullback of {3a ^ Psi^.) x A): 

R ^^A 

Y ' 

/ xA ^Ps{A) X A 

It follows from axiom (A2) that morphisms / Ps{A) are in bijective correspondence with 
5-relations {I R^ A). 

If every object of C has an 5-powerset, then the construction Pg extends straight- 
forwardly to a covariant endofunctor on C, as follows. For any morphism f : A ^ B, 
the action Ps{f) '■ Ps{A) — > Ps{B) corresponds to the 5-relation in the image of the span 
(PsiA) ^ 3a A ^ B), using axiom (A6). 

Separation and collection. There are various axioms and axiom schema that can be assumed 
as principles for defining sets in a constructive setting. The notes by Aczel and Rathjen ^ 
provide an overview. 

The separation axiom (also known as bounded comprehension) amounts to the following 
axiom on S. 

(M) All monomorphisms in C are in S. 

The (strong) collection axiom has the following categorical counterpart, when there is an 
5-powerset: 

(A9) The endofunctor Pg preserves covers. 

Further axioms. The axioms above are all that we need in this article. As a foundation of 
mathematics, these axioms are too weak: one would typically also require that there is a 
small natural numbers object; that each powerset Ps{X) is small; and that there is a class 
of all sets, a universal small map. 
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